Bug 2437111 (CVE-2025-68121)
| Summary: | CVE-2025-68121 crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | aazores, abarbaro, abrianik, adistefa, akostadi, akoudelk, alcohan, alebedev, alizardo, amasferr, amctagga, anjoseph, anpicker, ansmith, anthomas, aoconnor, asatyam, ataylor, bdettelb, bniver, bparees, chfoley, ckandaga, cmah, crizzo, csutherl, dbruscin, dhanak, diagrawa, dmayorov, doconnor, drosa, dschmidt, dsimansk, dsoumis, dymurray, eaguilar, ebaron, eborisov, eglynn, ehelms, erezende, ewittman, fdeutsch, flucifre, ggainey, ggrzybek, gmeno, gparvin, groman, hasun, ibolton, janstey, jbalunas, jburrell, jcantril, jchui, jclere, jeder, jfula, jhe, jjoyce, jkoehler, jlanda, jlledo, jmatthew, jmontleo, jolong, jowilson, jprabhak, jpretori, jraez, jschluet, jscholz, juwatts, kingland, kshier, ktsao, kvanderr, kverlaen, lball, lbragsta, lchilton, lgamliel, lhh, lphiri, manissin, mattdavi, matzew, mbenjamin, mbocek, mburns, mgarciac, mhackett, mhulan, mnovotny, mrunge, mwringe, nboldt, ngough, nipatil, nmoumoul, nyancey, oaljalju, ometelka, oramraz, osousa, pahickey, pantinor, parichar, pcreech, peholase, pgaikwad, pjindal, plodge, psrna, ptisnovs, pvasanth, rchan, rfreiman, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rkubis, rmaucher, rojacob, sabiswas, sakbas, sausingh, sdawley, sfeifer, simaishi, slucidi, smallamp, smalloy, smcdonal, smullick, sostapov, sseago, stcannon, stirabos, swoodman, syedriko, szappis, tasato, teagle, thason, tmalecek, tsedmik, tzivkovi, vereddy, veshanka, vimartin, vkarehfa, watson-tool-maintainers, wenshen, whayutin, wtam, xdharmai, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the crypto/tls component. This vulnerability occurs during Transport Layer Security (TLS) session resumption when certificate authority (CA) settings are modified between the initial and resumed handshakes. An attacker could exploit this to bypass certificate validation, allowing a client or server to establish a connection that should have been rejected. This could lead to an authentication bypass under specific conditions.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2439295 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-02-05 18:01:53 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:2706 https://access.redhat.com/errata/RHSA-2026:2706 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:2708 https://access.redhat.com/errata/RHSA-2026:2708 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:2709 https://access.redhat.com/errata/RHSA-2026:2709 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:2914 https://access.redhat.com/errata/RHSA-2026:2914 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:2920 https://access.redhat.com/errata/RHSA-2026:2920 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3035 https://access.redhat.com/errata/RHSA-2026:3035 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3040 https://access.redhat.com/errata/RHSA-2026:3040 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3092 https://access.redhat.com/errata/RHSA-2026:3092 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:3192 https://access.redhat.com/errata/RHSA-2026:3192 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:3187 https://access.redhat.com/errata/RHSA-2026:3187 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:3188 https://access.redhat.com/errata/RHSA-2026:3188 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:3193 https://access.redhat.com/errata/RHSA-2026:3193 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3291 https://access.redhat.com/errata/RHSA-2026:3291 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3297 https://access.redhat.com/errata/RHSA-2026:3297 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3297 https://access.redhat.com/errata/RHSA-2026:3297 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3297 https://access.redhat.com/errata/RHSA-2026:3297 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3298 https://access.redhat.com/errata/RHSA-2026:3298 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3298 https://access.redhat.com/errata/RHSA-2026:3298 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3298 https://access.redhat.com/errata/RHSA-2026:3298 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3336 https://access.redhat.com/errata/RHSA-2026:3336 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3336 https://access.redhat.com/errata/RHSA-2026:3336 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3336 https://access.redhat.com/errata/RHSA-2026:3336 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3337 https://access.redhat.com/errata/RHSA-2026:3337 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3343 https://access.redhat.com/errata/RHSA-2026:3343 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3341 https://access.redhat.com/errata/RHSA-2026:3341 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3340 https://access.redhat.com/errata/RHSA-2026:3340 This issue has been addressed in the following products: Cryostat 4 on RHEL 9 Via RHSA-2026:3186 https://access.redhat.com/errata/RHSA-2026:3186 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:3506 https://access.redhat.com/errata/RHSA-2026:3506 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3752 https://access.redhat.com/errata/RHSA-2026:3752 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3753 https://access.redhat.com/errata/RHSA-2026:3753 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:3816 https://access.redhat.com/errata/RHSA-2026:3816 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:3817 https://access.redhat.com/errata/RHSA-2026:3817 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:3831 https://access.redhat.com/errata/RHSA-2026:3831 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:3833 https://access.redhat.com/errata/RHSA-2026:3833 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3840 https://access.redhat.com/errata/RHSA-2026:3840 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:3843 https://access.redhat.com/errata/RHSA-2026:3843 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3839 https://access.redhat.com/errata/RHSA-2026:3839 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3842 https://access.redhat.com/errata/RHSA-2026:3842 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3864 https://access.redhat.com/errata/RHSA-2026:3864 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:3898 https://access.redhat.com/errata/RHSA-2026:3898 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3928 https://access.redhat.com/errata/RHSA-2026:3928 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:3929 https://access.redhat.com/errata/RHSA-2026:3929 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:3970 https://access.redhat.com/errata/RHSA-2026:3970 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3971 https://access.redhat.com/errata/RHSA-2026:3971 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:3977 https://access.redhat.com/errata/RHSA-2026:3977 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:3985 https://access.redhat.com/errata/RHSA-2026:3985 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:4166 https://access.redhat.com/errata/RHSA-2026:4166 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:4164 https://access.redhat.com/errata/RHSA-2026:4164 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:4174 https://access.redhat.com/errata/RHSA-2026:4174 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:4177 https://access.redhat.com/errata/RHSA-2026:4177 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:4256 https://access.redhat.com/errata/RHSA-2026:4256 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:4264 https://access.redhat.com/errata/RHSA-2026:4264 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:4267 https://access.redhat.com/errata/RHSA-2026:4267 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:4672 https://access.redhat.com/errata/RHSA-2026:4672 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:4892 https://access.redhat.com/errata/RHSA-2026:4892 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:4907 https://access.redhat.com/errata/RHSA-2026:4907 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:4901 https://access.redhat.com/errata/RHSA-2026:4901 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:4952 https://access.redhat.com/errata/RHSA-2026:4952 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:5146 https://access.redhat.com/errata/RHSA-2026:5146 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:5077 https://access.redhat.com/errata/RHSA-2026:5077 This issue has been addressed in the following products: Red Hat Satellite 6.17 for RHEL 9 Via RHSA-2026:5970 https://access.redhat.com/errata/RHSA-2026:5970 This issue has been addressed in the following products: Red Hat Satellite 6.16 for RHEL 8 Red Hat Satellite 6.16 for RHEL 9 Via RHSA-2026:5971 https://access.redhat.com/errata/RHSA-2026:5971 This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.6 for RHEL 9 Red Hat Ansible Automation Platform 2.6 for RHEL 10 Via RHSA-2026:6277 https://access.redhat.com/errata/RHSA-2026:6277 This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.5 for RHEL 8 Red Hat Ansible Automation Platform 2.5 for RHEL 9 Via RHSA-2026:6278 https://access.redhat.com/errata/RHSA-2026:6278 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2026:5866 https://access.redhat.com/errata/RHSA-2026:5866 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2026:5876 https://access.redhat.com/errata/RHSA-2026:5876 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2026:6552 https://access.redhat.com/errata/RHSA-2026:6552 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:7854 https://access.redhat.com/errata/RHSA-2026:7854 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:9097 https://access.redhat.com/errata/RHSA-2026:9097 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:9098 https://access.redhat.com/errata/RHSA-2026:9098 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:9109 https://access.redhat.com/errata/RHSA-2026:9109 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:9108 https://access.redhat.com/errata/RHSA-2026:9108 This issue has been addressed in the following products: Red Hat OpenStack Services on OpenShift 18.0 Via RHSA-2026:7885 https://access.redhat.com/errata/RHSA-2026:7885 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:11749 https://access.redhat.com/errata/RHSA-2026:11749 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:12029 https://access.redhat.com/errata/RHSA-2026:12029 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:12028 https://access.redhat.com/errata/RHSA-2026:12028 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:12031 https://access.redhat.com/errata/RHSA-2026:12031 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:12030 https://access.redhat.com/errata/RHSA-2026:12030 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:12032 https://access.redhat.com/errata/RHSA-2026:12032 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:12033 https://access.redhat.com/errata/RHSA-2026:12033 This issue has been addressed in the following products: Streams for Apache Kafka 3.2.0 Via RHSA-2026:13571 https://access.redhat.com/errata/RHSA-2026:13571 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:14868 https://access.redhat.com/errata/RHSA-2026:14868 |